Skip to content

Why Supply Chain Risk Is Becoming the Next Big Challenge for CyFun Compliance

by Deepak Xavier, chief product officer on

An organization can have strong firewalls.

Mature identity controls.

Well-trained employees.

Advanced security monitoring.

And still experience a cybersecurity incident through a third party.

That is the reality of the modern digital supply chain.

Today's organizations depend on an expanding ecosystem of:

  • Cloud providers
  • SaaS platforms
  • Managed service providers
  • Software vendors
  • Data processors
  • Technology partners
  • Contractors
  • Outsourced operations

Cybersecurity is no longer limited to the infrastructure an organization owns.

It increasingly depends on the security of organizations it connects with.

This is one of the reasons CyFun 2025 expanded its focus on supply-chain security. The updated framework also aligns with NIST CSF 2.0 and broader European cybersecurity expectations.

For compliance and cybersecurity teams, this creates a major challenge:

How do you continuously manage cybersecurity risk when part of your technology environment belongs to someone else?

The Third-Party Security Illusion

Many organizations believe they manage vendor risk because they have a vendor questionnaire.

The process often looks like this:

  1. A vendor is selected.
  2. A security questionnaire is sent.
  3. Documents are reviewed.
  4. The vendor is approved.
  5. The assessment is repeated next year.

The problem is that cybersecurity risk does not remain unchanged for 12 months.

Between assessments, a vendor may:

  • Change its infrastructure.
  • Add subcontractors.
  • Introduce AI capabilities.
  • Experience an incident.
  • Change access permissions.
  • Expand data processing activities.
  • Introduce new software dependencies.

The annual questionnaire can therefore create a false sense of assurance.

A completed questionnaire proves what the organization knew at one moment. It does not automatically prove ongoing security.

Why CyFun 2025 Is Putting More Focus on Supply Chains

CyFun 2025 specifically expands its focus on supply-chain security.

This follows a broader international trend.

NIST CSF 2.0 also increased emphasis on cybersecurity supply-chain risk management, reflecting the growing importance of third-party and ecosystem risks.

The reason is simple.

Organizations are becoming more interconnected.

A modern business may rely on dozens or hundreds of external technology relationships.

The cybersecurity perimeter has expanded beyond the traditional enterprise boundary.

The New Cybersecurity Perimeter Is an Ecosystem

The old model of cybersecurity focused on protecting:

Our network.

The modern model needs to consider:

Our ecosystem.

That ecosystem may include:

Technology Providers

Cloud platforms, SaaS tools and infrastructure providers.

Data Partners

Organizations processing or storing sensitive information.

Managed Service Providers

Third parties with privileged access to systems.

Software Dependencies

External libraries, APIs and development tools.

AI Providers

Models and services integrated into business processes.

Every connection can introduce risk.

The Four Supply-Chain Questions Organizations Need to Answer

A modern CyFun program should help organizations answer four ongoing questions.

1. Who Has Access?

Organizations need visibility into:

  • Vendors with system access
  • Privileged access relationships
  • Data access
  • Remote access
  • Third-party integrations

2. What Do They Have Access To?

Not every vendor relationship carries the same risk.

Access to a public website is different from access to:

  • Sensitive citizen data
  • Financial information
  • Production systems
  • Critical infrastructure
  • Identity platforms

Risk management needs context.

3. What Security Obligations Apply?

Organizations should define appropriate requirements based on risk.

These may include:

  • Security controls
  • Incident notification expectations
  • Access restrictions
  • Data protection requirements
  • Audit rights
  • Evidence requirements

4. What Has Changed?

This is where continuous assurance becomes important.

Organizations should avoid treating third-party risk as static.

Risk can change when:

  • Systems are integrated.
  • Access expands.
  • Data flows change.
  • Vendors change subcontractors.
  • New technology is introduced.

The Growing Problem of AI in the Supply Chain

One of the newest supply-chain challenges is AI.

A software vendor may suddenly introduce:

  • AI assistants
  • Automated decision-making
  • Generative AI features
  • Agentic workflows

These changes may affect:

  • Data flows
  • Privacy
  • Security
  • Access permissions
  • Model risk

The World Economic Forum's 2026 cybersecurity analysis highlights how AI adoption is creating assurance challenges and pushing organizations toward more continuous approaches to validation and security assessment.

For third-party risk teams, this means vendor due diligence is becoming more complex.

It is no longer enough to ask:

"Is this vendor secure?"

Organizations may need to ask:

"How is this vendor changing?"

Moving From Vendor Assessments to Vendor Assurance

There is an important difference.

Vendor Assessment

A periodic review of a vendor's security posture.

Vendor Assurance

An ongoing approach to maintaining confidence in a vendor relationship.

The second approach requires more than questionnaires.

It requires:

  • Risk classification
  • Control requirements
  • Evidence
  • Ownership
  • Change monitoring
  • Issue management

A Practical CyFun Supply-Chain Operating Model

Step 1: Create a Vendor Risk Inventory

Centralize information about vendors and technology partners.

Track:

  • Services provided
  • Data involved
  • Access levels
  • System dependencies
  • Business criticality

Step 2: Classify Risk

Not every supplier requires the same level of oversight.

Risk classification can consider:

  • Data sensitivity
  • Access privileges
  • Service criticality
  • Regulatory impact
  • Operational dependency

Step 3: Map Relevant Controls

Map cybersecurity requirements to vendor relationships.

This reduces ad hoc assessments and creates consistency.

Step 4: Define Evidence Expectations

Determine what evidence is required from high-risk relationships.

Step 5: Track Changes

Maintain visibility into changes that could affect risk.

Step 6: Manage Findings

Vendor findings should follow structured remediation workflows.

A risk identified during assessment should not disappear into an email thread.

How Quantarra Helps Manage CyFun Supply-Chain Risk

Quantarra helps organizations centralize compliance and risk operations across complex environments.

For supply-chain cybersecurity, organizations can use a connected operating model to manage:

  • Controls
  • Risks
  • Evidence
  • Assessments
  • Ownership
  • Findings
  • Remediation

Cross-framework mapping can also help organizations avoid recreating vendor requirements for every cybersecurity or regulatory framework.

The objective is to create one clearer view of cyber risk across the extended enterprise.

Conclusion

Supply-chain cybersecurity is becoming one of the defining challenges of modern compliance.

The question is no longer whether your organization has strong cybersecurity controls internally.

It is whether you can maintain confidence across the broader ecosystem your organization depends on.

CyFun 2025's increased focus on supply-chain security reflects this changing reality.

The organizations that continue treating vendor security as an annual questionnaire exercise may struggle to keep pace.

The future is moving toward:

Connected risk. Continuous visibility. Ongoing assurance.